by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors KiviCare – Clinic & Patient Management System (EHR) (slug: kivicare-clinic-management-system) has a Medium severity vulnerability (CVSS 6.5, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) tracked as CVE-2026-25022. The issue affects versions up to...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors CVE-2026-24958 affects the JetElements For Elementor WordPress plugin (JetElements, slug: jet-elements) in versions up to and including 2.7.12.2. This is a Medium severity issue (CVSS 6.4) involving stored cross-site scripting (XSS), which means...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors Seriously Simple Podcasting (slug: seriously-simple-podcasting) has a Medium-severity issue (CVSS 6.4) identified as CVE-2026-24952. This is an authenticated Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 3.14.1....
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors Better Search – Relevant search results for WordPress (slug: better-search) is affected by an authenticated (Author+) Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 4.2.1. The reported severity is Medium (CVSS 6.4). This...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors WP Job Portal – AI-Powered Recruitment System for Company or Job Board website (slug: wp-job-portal) has a medium-severity vulnerability (CVE-2026-24941, CVSS 5.3) related to missing authorization. In practical terms, this means an external attacker...
by Ivan Sorkin | Feb 10, 2026 | Plugins
Attack Vectors CVE-2026-24944 affects the WordPress plugin Subscribe2 – Form, Email Subscribers & Newsletters (slug: subscribe2) in versions 10.44 and earlier. The severity is Medium (CVSS 5.3). The core risk is exposure to unauthenticated requests (no login...
Recent Comments